<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can i add a filter task to my IDS receive a warnning mes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435435#M67316</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Jun 2010 15:07:55 GMT</pubDate>
    <dc:creator>anas.belahcen</dc:creator>
    <dc:date>2010-06-04T15:07:55Z</dc:date>
    <item>
      <title>how can i add a filter task to my IDS receive a warnning message when users make authentification windows or Active directory to servers</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435426#M67293</link>
      <description>&lt;P&gt;i have an IDS 4215 ,and i want that it give me a warnning when users make authentification windows or actice directory to some servers.should i add a signature or what?and i want to specify the servers which the warnning will be available. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435426#M67293</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2019-03-10T12:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435427#M67296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this would be the ideal candidate for a custom signature.&amp;nbsp; You can find out more about writing signatures for Cisco IPS sensors here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_signature_definitions.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_signature_definitions.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also make use of the Signature Wizard for assisted creation.&amp;nbsp; More details can be found here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the IPS sensor to fire a signature when your criteria are matched.&amp;nbsp; Should you want an email alert to be generated for that signature event, you will need to implement a solution such as Cisco's free IPS Manager Express (IME).&amp;nbsp; You can find out more, and download IME here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/ime"&gt;http://www.cisco.com/go/ime&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 11:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435427#M67296</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-03T11:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435428#M67298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you ,but can you give me one exemple of custome signature with configuration to make it in the sensor.&lt;/P&gt;&lt;P&gt;because i didn't found where to put for exemple the @ip of servers which i want to make warnning for them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 15:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435428#M67298</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2010-06-03T15:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435429#M67300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depending on whether the servers in question are the source (attacker) of the traffic or destination (victim) will determine where you would place the server IP addresses in the signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a simple signature definition using a signature variable for multiple IP address storage. This signature is in no way designed to detect the exact behavior you are interested in capturing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: terminal,monaco; font-size: 8pt;"&gt;signatures 60001 0 &lt;BR /&gt;sig-description&lt;BR /&gt;sig-name Atomic IP Detection&lt;BR /&gt;sig-string-info An IP address of interest was detected.&lt;BR /&gt;exit&lt;BR /&gt;engine atomic-ip&lt;BR /&gt;specify-ip-addr-options yes&lt;BR /&gt;ip-addr-options ip-addr&lt;BR /&gt;specify-src-ip-addr yes&lt;BR /&gt;src-ip-addr $SERVERS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will, of course, need to choose the approriate signature engine to provide inspection to meet your requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 16:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435429#M67300</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-03T16:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435430#M67302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so with this configuration !! i will receive a warnning when one of users will make a log windows.???&lt;/P&gt;&lt;P&gt;tank you for collaboration&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 14:43:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435430#M67302</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2010-06-04T14:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435431#M67304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the above was just a&amp;nbsp; sample signature on how to add a variable as the source IP address in a signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to determine the traffic profile for the behavior for which you are attempting to create a signature.&amp;nbsp; You may be able to do this by performing packet captures using Wireshark, or a similar tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you determine what the traffic looks like, you can determine the correct signature engine to use, and what specific details need to be caught by the signature.&amp;nbsp; Not having access to your network, I cannot create a solution to meet your needs.&amp;nbsp; This is an activity that you will need to perform on your own.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are wanting to monitor logins to Windows servers, it may be better to implement audit logging on the servers in question, and monitor those access for these activities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 14:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435431#M67304</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-04T14:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435432#M67306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how you can help me ,if i wanna just have a warnning for a log windows in some servers .or try just for one.&lt;/P&gt;&lt;P&gt;the exemple is : when for exemple i'll make a log windiw in server x the IDS will give me a warnning for the log to tell me some one makes a log windows in server x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 14:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435432#M67306</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2010-06-04T14:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435433#M67309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes ,i can but i'll not receive a warnning message&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 14:54:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435433#M67309</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2010-06-04T14:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435434#M67312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot write a specific signature for you since I do not have access to your network to see exactly what packets traverse the network during the activity you are wanting to alert on.&amp;nbsp; This is effort you will need to perform yourself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are several signatures already present on the IPS sensor that detect failed logons and such (5606/0, 5726/0-1, 5739/0-1), you may be able to use one of these signatures as a basis for creating a custom signature to detect a successful logon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this logon activity takes place using an encrypted channel, the IPS will not be able to detect this activity and alert you since the IPS cannot decrypt this communication.&amp;nbsp; The most effective manner for monitoring Windows server logins is through the monitoring of the local Windows event logs via a remote monitoring tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 15:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435434#M67312</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-04T15:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add a filter task to my IDS receive a warnning mes</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435435#M67316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 15:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-add-a-filter-task-to-my-ids-receive-a-warnning-message/m-p/1435435#M67316</guid>
      <dc:creator>anas.belahcen</dc:creator>
      <dc:date>2010-06-04T15:07:55Z</dc:date>
    </item>
  </channel>
</rss>

